1
You don't seem to have a security forum so I don't know where to post this. Feel free to move the post.
PopnupBlog index.php multiple variables Cross-Site Scripting
PopnupBlog contains a flaw that allows a remote cross site scripting attack.This flaw exists because
the application does not validate 'param' , 'cat_id' and 'view' variables upon submission to 'index.php' script.
This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within
the trust relationship between the browser and the server, leading loss ofintegrity.
More...